this post was submitted on 27 Mar 2025
7 points (81.8% liked)

Cybersecurity

6869 readers
49 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[โ€“] drspod@lemmy.ml 5 points 3 days ago

SMS messages are not encrypted. Theoretically, this allows telecommunications providers to scan for and blacklist spam campaigns at the network level, if they make enough noise. On the other hand, messages sent via RCS or iMessage are encrypted end-to-end. Although an iMessage will route directly through an Apple server, Apple itself cannot read the content in transit. Lucid takes advantage of this by sending phishing texts via iMessage and RCS, turning this otherwise positive security feature on its head.

That's it. That's the "fault" that is being "exploited" that they mention multiple times in the lead-in to the article.

Hehe this came up minutes after receiving an RCS phishing message pretending to be Amazon ๐Ÿ˜„